Use-After-Free Vulnerability in BusyBox by BusyBox
CVE-2023-42363

5.5MEDIUM

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
27 November 2023

What is CVE-2023-42363?

A use-after-free vulnerability has been identified in the xasprintf function located in xfuncs_printf.c at line 344 of BusyBox version 1.36.1. This flaw can lead to significant security risks as it allows attackers to exploit memory management bugs, potentially enabling arbitrary code execution or further compromises within the system. It is crucial for users of the affected version to address this security issue promptly to mitigate the risks.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.